CVE-2025-24113

MEDIUM EXPLOITED

Safari < 18.3 - User Interface Spoofing via Malicious Website

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-24113 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2026-04-07
Status published
Products (15)
Apple/iOS and iPadOS < 18.3
Apple/iOS and iPadOS < 18.4
Apple/iPadOS < 17.7.6
apple/ipados < 18.3
apple/iphone_os < 18.3
apple/macos < 15.3
Apple/macOS < 15.3
Apple/macOS < 15.4
apple/safari < 18.3
Apple/Safari < 18.3
... and 5 more
Published Jan 27, 2025
Tracked Since Feb 18, 2026